Atlas / MCP servers / snseam / BOSS Zhipin

BOSS ZhipinSAFE

mcp/snseam/boss-zhipin

BOSS直聘 MCP Server — 用 AI 自动化招聘流程:批量搜索候选人、简历截图OCR、智能评估、多关键词筛选 | BOSS Zhipin Recruiter Automation via Model Context Protocol

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
17 14r · 2w · 1d
Transport
streamable-http
License
—
Stars
142
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

用 AI 自动化 BOSS 直聘招聘流程 — 批量搜索、自动获取链接、智能筛选评分、一键导出报告

[](https://modelcontextprotocol.io) [](https://python.org) [](LICENSE)

BOSS 直聘 (zhipin.com) 招聘者端自动化工具,基于 Model Context Protocol (MCP),让 Claude Code / Claude Desktop 等 AI 助手直接操作 BOSS 直聘招聘后台。

功能特性

  • 候选人搜索 — 在 BOSS 直聘「找人才」页面搜索,支持滚动加载 100+ 候选人
  • 多关键词批量搜索 — 12+ 关键词自动轮询 + 跨关键词去重 + 每个关键词搜索后自动获取分享链接
  • 候选人数据库 — 搜索结果自动持久化到本地 JSON 数据库,中断可恢复,数据不丢失
  • 简历查看 — 点击候选人卡片,自动截图 Canvas 渲染的简历(绕过防爬)
  • 分享链接提取 — 自动点击转发按钮,解码 QR 码获取 zpurl.cn 永久链接
  • 一键打招呼 — 在搜索结果中直接对候选人发起沟通,进入 BOSS 聊天列表
  • 自动筛选评分 — 按 YAML 配置的条件(年龄/薪资/状态)过滤 + 多维度评分
  • 报告导出 — 一键生成 Markdown 候选人报告(表格 + 跟进表 + 详情卡片)
  • 浏览器自动启动 — 未检测到 Chrome debug 端口时,自动启动系统 Chrome
  • YAML 配置 — 公司信息、JD、搜索关键词、筛选条件全部可配置

工作原理

Claude Code / Claude Desktop
↓ MCP (stdio)
boss-zhipin-mcp (FastMCP Server)
↓ CDP (Chrome DevTools Protocol)
Chrome 浏览器 (已登录 BOSS 直聘)
↓
BOSS 直聘招聘者后台 (zhipin.com)

通过 Playwright 连接你已登录的 Chrome 浏览器,在 BOSS 直聘的 SPA 页面内操作搜索、查看、发消息等功能。

完整招聘流水线

boss_multi_search(auto_view=True)
│
│  ┌─── 关键词循环 (12次) ────────────────────────┐
│  │  1. 搜索关键词 → 页面加载候选人卡片           │
│  │  2. 去重 + 存入数据库                         │
│  │  3. 全量 view 所有新候选人 → 获取 share_url   │
│  │  4. 切换下一个关键词                          │
│  └──────────────────────────────────────────────┘
│  结果: 所有候选人有 share_url + 完整数据在 DB
▼
boss_filter_and_score(top_n=15)     ← 自动筛选+评分
▼
boss_export_report(top_n=15)        ← 生成 Markdown 报告
▼
boss_greet_by_index() / boss_send_greeting()  ← 联系候选人

快速开始

1. 安装

git clone https://github.com/Snseam/boss-zhipin-mcp.git
cd boss-zhipin-mcp
python -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
playwright install chromium

2. 配置搜索条件

cp s
Read from source at commit dd62570a6bfeOBSERVED · 2026-10-07
02

Exposed tools (17)

14 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
boss_clear_dedupdestructive选择性清除去重记录。
boss_debug_pageread调试工具:全面扫描当前页面 DOM 结构。
boss_evaluate_candidatereadAI 评估候选人与岗位匹配度。
boss_export_reportread从数据库导出候选人报告(Markdown 格式)。
boss_filter_and_scoreread自动筛选 + 评分数据库中的候选人。
boss_greet_by_indexread在搜索结果中直接对候选人打招呼/发起沟通。
boss_loginread登录 BOSS 直聘招聘者账号。
boss_multi_searchread多关键词批量搜索候选人,自动去重,自动获取分享链接。
boss_pipeline_statusread查看当前招聘流水线进度。
boss_query_dbread查询候选人数据库,支持按状态/链接/关键词/日期筛选。
boss_reloadread热重载所有模块代码,无需重启 server。
boss_search_candidatesread在 BOSS 直聘「找人才」页面搜索候选人。
boss_send_greetingwrite向候选人发送打招呼消息。
boss_update_candidatewrite更新候选人状态、评分或备注。
boss_view_by_expect_idread通过 expectId 在当前搜索页面查找候选人并查看简历。
boss_view_by_indexread点击搜索结果中第 N 个候选人,查看详细简历并提取分享链接。
boss_view_candidateread查看候选人详细简历。
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
UNDECLARED (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
boss_clear_dedup
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
scraper.py:520
img_bytes = base64.b64decode(b64)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
fastmcp, playwright, anthropic, pyyaml, pillow, pyzbar
Why it matters. 6 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha dd62570a6bfefull audit observations/trust-audit/mcp-server/snseam__boss-zhipin.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07dd62570a6bfeSAFEB89first audit
05

Questions

What is the BOSS Zhipin MCP server?

BOSS直聘 MCP Server — 用 AI 自动化招聘流程:批量搜索候选人、简历截图OCR、智能评估、多关键词筛选 | BOSS Zhipin Recruiter Automation via Model Context Protocol

What tools does BOSS Zhipin expose?

17 in total: 14 read-only, 2 that write, and 1 that can delete or overwrite (boss_clear_dedup). Every one is listed on this page with its risk.

Is BOSS Zhipin safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does BOSS Zhipin need?

It reads ANTHROPIC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does BOSS Zhipin run?

It speaks streamable-http, so it runs as a service you connect to over the network.

How current is this page?

The grade is for one exact copy of the source (dd62570a6bfe), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement